Ive studied this entire site looking through the tips and stickies… Ive downloaded CCleaner done the scan as well as other things and still I cant get rid of this Avast Pop up that comes up every 5 minutes saying 213.155.31.136/serv/gate.php was blocked.
Its driving me nuts…any help is greatly appreciated.
I have the CCleaner report but it says its to much to many characters for this post.
On completion of the scan click save log, save it to your desktop and post in your next reply
THEN
Download OTS to your Desktop and double-click on it to run it
[*]Make sure you close all other programs and don’t use the PC while the scan runs.
[*]Select All Users
[*]Under additional scans select the following Reg - Disabled MS Config Items
Reg - Drivers32
Reg - NetSvcs
Reg - SafeBoot Minimal
Reg - Shell Spawning
Evnt - EventViewer Logs (Last 10 Errors)
File - Lop Check
[*]Now click the Run Scan button on the toolbar. Make sure not to use the PC while the program is running or it will freeze.
[*]When the scan is complete Notepad will open with the report file loaded in it.
[*]Please attach the log in your next post.
A malicious Java file that exploit one or more vulnerabilities, after essexboy’s cleansing routine you should update all the software on that computer after an online scan here: http://secunia.com/vulnerability_scanning/online/?task=load
But from the connections made, we have to conclude you probably have a SpyEye infection,
When a SpyEye bot running on an infected computer starts up, it immediately sends a message to check in with its Command & Control server. This first message contains some basic information about the bot infector and the computer it is running on. Here is an example, with the parameters highlighted.
The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here
I will review the information when it comes back in.
All Processes Killed
[Driver Services - Safe List]
Error: No service named MpKsl7bb8f3db was found to stop!
Service\Driver key MpKsl7bb8f3db not found.
File not found.
Error: No service named Avgtdix was found to stop!
Service\Driver key Avgtdix not found.
File not found.
Error: No service named Avgrkx86 was found to stop!
Service\Driver key Avgrkx86 not found.
File not found.
Error: No service named AVGIDSShim was found to stop!
Service\Driver key AVGIDSShim not found.
File not found.
Error: No service named AVGIDSFilter was found to stop!
Service\Driver key AVGIDSFilter not found.
File not found.
Error: No service named AVGIDSEH was found to stop!
Service\Driver key AVGIDSEH not found.
File not found.
Error: No service named AVGIDSDriver was found to stop!
Service\Driver key AVGIDSDriver not found.
File not found.
[Registry - Safe List]
File C:\PROGRAM FILES\AVG\AVG10\FIREFOX not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{DBC80044-A445-435b-BC74-9C25C1C588A9}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{DBC80044-A445-435b-BC74-9C25C1C588A9}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\MRI_DISABLED\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar\{0BF43445-2F28-4351-9252-17FE6E806AA0} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{0BF43445-2F28-4351-9252-17FE6E806AA0}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found.
Registry value HKEY_USERS\S-1-5-21-3570320739-1737594718-479680718-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{472734EA-242A-422B-ADF8-83D1E48CC825} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{472734EA-242A-422B-ADF8-83D1E48CC825}\ not found.
Registry value HKEY_USERS\S-1-5-21-3570320739-1737594718-479680718-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\AvgUninstallURL not found.
Registry value HKEY_USERS\S-1-5-21-3570320739-1737594718-479680718-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\B8FD6570F25AE774 deleted successfully.
C:\ProgData\ProgData.exe moved successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2{0ee002ea-d3c3-11dd-8bbe-001e68eb7212}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{0ee002ea-d3c3-11dd-8bbe-001e68eb7212}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2{0ee002ea-d3c3-11dd-8bbe-001e68eb7212}\shell\AutoRun\command\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2{0ee002ea-d3c3-11dd-8bbe-001e68eb7212}\shell\AutoRun\command not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2{4a981831-d2df-11dd-b733-001e68eb7212}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{4a981831-d2df-11dd-b733-001e68eb7212}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2{4a981831-d2df-11dd-b733-001e68eb7212}\shell\AutoRun\command\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2{4a981831-d2df-11dd-b733-001e68eb7212}\shell\AutoRun\command not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2{6f554c96-c747-11de-8838-00238b0fe603}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{6f554c96-c747-11de-8838-00238b0fe603}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2{6f554c96-c747-11de-8838-00238b0fe603}\shell\AutoRun\command\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2{6f554c96-c747-11de-8838-00238b0fe603}\shell\AutoRun\command not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2{8a486086-f0b4-11de-be4c-00238b0fe603}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{8a486086-f0b4-11de-be4c-00238b0fe603}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2{8a486086-f0b4-11de-be4c-00238b0fe603}\shell\AutoRun\command\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2{8a486086-f0b4-11de-be4c-00238b0fe603}\shell\AutoRun\command not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2{9aac6711-dd08-11de-aac1-00238b0fe603}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{9aac6711-dd08-11de-aac1-00238b0fe603}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2{9aac6711-dd08-11de-aac1-00238b0fe603}\shell\AutoRun\command\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2{9aac6711-dd08-11de-aac1-00238b0fe603}\shell\AutoRun\command not found.
[File - Lop Check]
C:\Users\Owner\AppData\Roaming\AVG10\cfgall folder moved successfully.
C:\Users\Owner\AppData\Roaming\AVG10 folder moved successfully.
[Custom Items]
========== FILES ==========
C:\ProgData folder moved successfully.
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
c:\Users\Owner\Downloads\cmd.bat deleted successfully.
c:\Users\Owner\Downloads\cmd.txt deleted successfully.
C:\PROGRAM FILES\AVG\AVG10\Toolbar folder moved successfully.
C:\PROGRAM FILES\AVG\AVG10\Notification folder moved successfully.
C:\PROGRAM FILES\AVG\AVG10\Icons folder moved successfully.
C:\PROGRAM FILES\AVG\AVG10 folder moved successfully.
C:\PROGRAM FILES\AVG folder moved successfully.
[Empty Temp Folders]